This is exactly the issue - instead of 404-ing as expected, the page is rendered as 200 with whatever the value of “q” is as the collection object’s title so it’s outputted to the page, and that’s the exploit the spammers are taking advantage of.
Allan-EP
71
Related topics
| Topic | Replies | Views | Activity | |
|---|---|---|---|---|
| Is my site hacked with spammy fifa coin links? | 79 | 1108 | September 28, 2023 | |
| Shopify Big Bug: collections/vendors?q=XXXXXX | 44 | 801 | May 7, 2026 | |
| WARNING: /collections/vendors can be a HUGE security risk for your site | 37 | 776 | September 10, 2024 | |
| How can I prevent the new indexing bug from creating useless pages on Google? | 385 | 5743 | July 6, 2023 | |
| Loophole in Shopify stores (Chinese websites hacking attempts) | 31 | 393 | March 22, 2023 |